Real-world descriptions of how a group, tool or campaign used a technique.
68 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1559.001 Component Object Model |
GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| T1559.002 Dynamic Data Exchange |
GroupMuddyWater | MuddyWater has used malware that can execute PowerShell scripts via DDE. |
| T1560.001 Archive via Utility |
GroupMuddyWater | MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded. |
| T1566 Phishing |
GroupMuddyWater | MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1566.002 Spearphishing Link |
GroupMuddyWater | MuddyWater has sent targeted spearphishing e-mails with malicious links. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMuddyWater | MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone. |
| T1571 Non-Standard Port |
GroupMuddyWater | MuddyWater has used ports 8043 and 8848 for botnet C2 communication. |
| T1573.001 Symmetric Cryptography |
GroupMuddyWater | MuddyWater has used AES to encrypt C2 responses. |
| T1574.001 DLL |
GroupMuddyWater | MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware. |
| T1583.001 Domains |
GroupMuddyWater | MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1588.001 Malware |
GroupMuddyWater | MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals. |
| T1588.002 Tool |
GroupMuddyWater | MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment. |
| T1590.004 Network Topology |
GroupMuddyWater | MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors. |
| T1684.001 Impersonation |
GroupMuddyWater | MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell. |
| T1685 Disable or Modify Tools |
GroupMuddyWater | MuddyWater can disable the system's local proxy settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.